Impact
The flaw is a logic defect in macOS’s Gatekeeper system that can enable an application to bypass the built‑in code‑signing checks. This bypass allows unsigned or malicious software to run with the privileges of the installing user, potentially compromising confidentiality, integrity, and availability by providing the attacker with a local execution vector. The weakness is an instance of improper access control, as it permits execution that Gatekeeper is intended to prohibit.
Affected Systems
Apple macOS releases affected are macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, and macOS Tahoe 26.7. Earlier or later releases are considered unaffected unless Apple explicitly notes otherwise.
Risk and Exploitability
The CVSS score is not disclosed, and the EPSS score is unavailable, indicating no publicly available data on exploitation probability at this time. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploits. The likely attack vector is local: a user who installs an application that has circumvented Gatekeeper, requiring user interaction. If Gatekeeper is disabled or allows unsigned applications, the risk is elevated; otherwise the attacker must first trick or coerce the user to run a malicious package. Overall risk remains moderate to high for systems with Gatekeeper disabled or configured to allow non‑trusted installs, while enhanced controls can mitigate it.
OpenCVE Enrichment